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Amendments to the Claims : 

A listing of tlie entire set of pending claims (including amendments to the 
claims, if any) is submitted herewith per 37 CFR 1.121. This listing of claims will 
replace all prior versions, and listings, of claims in the application. 

Listing of Claims: 

1 . (Currently amended) A method of authorizing an operation on a machine 
requested by a first user on a content item comprisinq: i n accordanc e w i th 

receiving, at the machine, a user right certificate that identifies i dcntifv i na a 

second user and author i z i ng authorizes the second user to perform the requested 
operation on the content item, and i n wh i ch th e op e rat i on i s author i z e d 

authorizing the operation on the machine bv the first user upon receipt of 

information from the first use r, li nk i ng that links the first user and the us e r r i ght 
c e rtificat e of th e second use r as members of a common authorized domain . 

2. (Currently amended) The method of claim 1 , i n wh i ch wherein the information 
comprises one or more domain certificates identifying the first and second users as 
members of the same-authorized domain. 

3. (Currently amended) The method of claim 2, i n wh i ch wherein the one or more 
domain certificates comprise a first domain certificate identifying the first user as a 
member of afi -the authorized domain, and a second domain certificate identifying the 
second user as a member of the authorized domain. 

4. (Currently amended) The method of claim 2, i n wh i ch w herein the one or more 
domain certificates comprise a single certificate identifying the first and second users 
as members of the authorized domain. 

5. (Currently amended) The method of claim 1 , in wh i ch wherein the operation 
comprises at least one of: a rendering of the content item, a recording of the content 
item, a transfer of the content item and a creation of a copy of the content item. 



NL02 1063 Amend 9.0219 



Atty. Docket No. NL021063US 



Appl. No. 10/531,939 

Response to Office action of 19 February 2009 



Page 3 of 9 



6. (Previously presented) The method of claim 2, comprising receiving a content right 
containing necessary information for performing the requested operation on the 
content item, the user right certificate of the second user authorizing the second user 
to perform the requested operation using the content right. 

7. (Currently amended) The method of claim 6, i n wh i ch w herein the operation is not 
authorized if the content right does not identify the authorized domain. 

8. (Currently amended) A device arranged to perform an operation requested by a 
first user on a content item comprising: i n accordance with 

a receiving unit that is configured to receive a user right certificate i d e nt i fy i ng 

that identifies a second user and author i z i ng authorizes the second user to perform 
the requested operation on the content item, b ei ng arrang e d and 

an authorization unit that is configured to authorize the operation upon receipt 

of information from the first user Uf^kifng- that links the first user and the us e r r i gh t 
c e rt i f i cat e of th e second use r as members of a common authorized domain . 

9. (Currently amended) The device of claim 8, in wh i ch w herein the information 
comprises one or more domain certificates identifying the first and second users as 
members of the sam e authorized domain. 

10. (Currently amended) The device of claim 9, i n wh i ch wherein the one or more 
domain certificates comprise a first domain certificate identifying the first user as a 
member of an -the authorized domain, and a second domain certificate identifying the 
second user as a member of the authorized domain. 

1 1 . (Currently amended) The device of claim 9, i n which wherein the one or more 
domain certificates comprise a single certificate identifying the first and second users 
as members of the authorized domain. 
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12. (Original) Tlie device of claim 9, being arranged to receive an identifier for the 
first user from an identification device and to perform the operation if the received 
identifier matches the identification of the first user in the one or more domain 
certificates. 

13. (Original) The device of claim 8 or 9, being arranged to receive a content right 
containing necessary information for performing the requested operation on the 
content item, the user right certificate of the second user authorizing the second user 
to perform the requested operation using the content right. 

14. (Currently amended) The device of claim 1 1 , i n wh i ch w herein at least a portion 
of the content right is encrypted using an encryption key for which a corresponding 
decryption key is available to the device. 

15. (Currently amended) The device of claim 13, i n wh i ch wherein the content right is 
provided with a digital signature allowing verification of the authenticity of the content 
right. 

16. (Original) The device of claim 15, being arranged to perform the operation if the 
digital signature can be verified successfully using a digital certificate associated with 
an authorized content provider. 

17. (Original) The device of claim 15, being arranged to perform the operation if the 
digital signature can be verified successfully using a digital certificate associated with 
a particular device. 

18. (Original) The device of claim 15, being arranged to refuse to perform the 
operation if the digital signature cannot be verified successfully using a digital 
certificate associated with an authorized content provider and a digital watermark 
associated with the authorized content provider is present in the content item. 
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19. (Previously presented) The device of claim 15, being arranged to extract a public 
key from the content right and to use the extracted public key in determining whether 
the operation is authorized. 

20. (Original) The device of claim 13, being arranged to determine a robust fingerprint 
for the content item and to refuse to perform the operation if the determined robust 
fingerprint does not match a robust fingerprint comprised in the content right. 

21 . (Previously presented) The device of claim 9, being arranged to receive a content 
right containing necessary information for performing the requested operation on the 
content item, the user right certificate of the second user authorizing the second user 
to perform the requested operation using the content right, and to refuse to perform 
the operation if the authorized domain is not identified by the content right. 

22-30 (Canceled) 

31 . (Previously presented) The method of claim 1 , comprising receiving a content 
right containing necessary information for performing the requested operation on the 
content item, the user right certificate of the second user authorizing the second user 
to perform the requested operation using the content right. 

32. (Previously presented) The device of claim 13, being arranged to extract a public 
key from the content right and to use the extracted public key in determining whether 
the operation is authorized. 
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